835 Commits (f8362d04e4d46c44ab07beffb77cdd041af193c0)

Author SHA1 Message Date
Tim Möhlmann 284d54190a
Upgrade PyYAML to 4.2b4 7 years ago
hoellen dda64fe91e allow to disable aliases or users for domains and don't allow negativ values on domain creation/edit 7 years ago
hoellen 8fe1e788b3 add missing route fixes 7 years ago
Tim Möhlmann 3c7bf58211
Upgrade PyYAML
CVE-2017-18342
Vulnerable versions: < 4.2b1
Patched version: 4.2b1
In PyYAML before 4.1, the yaml.load() API could execute arbitrary code. In other words, yaml.safe_load is not used.
7 years ago
hoellen d5d4d6c337 harden email address validation and fix routes with user_email 7 years ago
Ionut Filip 01ec6e7bf3 Removed undefined function 7 years ago
mergify[bot] d483ef3c2a
Merge pull request #792 from hoellen/admin-broken-links-1
fix broken webmail and logo url in admin
7 years ago
Tim Möhlmann 74fe177297
Merge pull request #785 from TheLegend875/feat-displayed-name
Feature: send auto reply with displayed name
7 years ago
hoellen f617e82c06 fix broken webmail and logo url in admin 7 years ago
Tim Möhlmann 4068c5b751
Versioning for mysqlclient and psycopg2 7 years ago
Tim Möhlmann b2823c23b8
Merge remote-tracking branch 'upstream/master' into feat-psql-support 7 years ago
Tim Möhlmann 9eaeb80a27
Finalize merge with kaiyou/feat-multiple-db 7 years ago
TheLegend875 999d2a9557 changed default.sieve to send displayed name 7 years ago
TheLegend875 2954d84790 added necessary ui elements 7 years ago
TheLegend875 56f4d4c894 fixed auto-forward 7 years ago
TheLegend875 5bdbbf60d7 fixed display of username when not logged in 7 years ago
Dario Ernst c2d45a47fe Attempt stripping recipient delimiter from localpart
Since postfix now asks us for the complete email over podop, which
includes the recipient-delimiter-and-what-follows not stripped, we need
to attempt to find both the verbatim localpart, as well as the localpart
stripped of the delimited part ….

Fixes #755
7 years ago
Tim Möhlmann 19df86f13f
Merge pull request #764 from usrpro/fix-alias-bug
Added regex validation for alias username
7 years ago
Tim Möhlmann 3a5b763018
Option to disable full text search (lucene)
This is a workaround for the bug in issue #751
7 years ago
mergify-bot 983c388150 Merge branch 'master' into 'fix-localpart-chars' 7 years ago
mergify-bot 6cfb74e96c Merge branch 'master' into 'fix-localpart-chars' 7 years ago
Tim Möhlmann af086bbdbe
Include DKIM in VOLUME 7 years ago
hoellen c041a9d45c allow all characters for username in dovecot 7 years ago
Tim Möhlmann 24828615cf
Webmail on root, fixes #757 7 years ago
Ionut Filip 8fc2846924 Added regex validation for alias username 7 years ago
Tim Möhlmann 3c4ee1b31e
Merge pull request #743 from kaiyou/master
Fixes #738 regarding application context
7 years ago
ofthesun9 97b3a85090
Merge pull request #737 from hoellen/fix-alias-match-behaviour
fix alias match behaviour
7 years ago
mergify-bot 09a50b6cfc Merge branch 'master' into 'master' 7 years ago
kaiyou 4060ac2223 Remove some forgotten debugging 7 years ago
kaiyou 087841d5b7 Fix the way we handle the application context
The init script was pushing an application context, which maked
flask.g global and persisted across requests. This was evaluated
to have a minimal security impact.

This explains/fixes #738: flask_wtf caches the csrf token in the
application context to have a single token per request, and only
sets the session attribute after the first generation.
7 years ago
kaiyou b5f51b0e2e Update python dependencies 7 years ago
kaiyou 8707b0fcd7 Use a dictionary of db connection string templates 7 years ago
kaiyou 19f18e2240 Lowercase relays as well as other tables 7 years ago
kaiyou 7e388e472a Handle relay name as an Idna domain 7 years ago
kaiyou 871aa14c9a Lowercase every domain name and email 7 years ago
kaiyou 3df9b3962d Add default columns to the configuration table 7 years ago
kaiyou b88f61f183 Name all constraints when creating them
Prefious commit set the constraint names for existing databases.
New databases can now have named constraints from the ground up.
7 years ago
kaiyou b8282b1d46 Support named constraints for multiple backends
Supporting multiple backends requires that specific sqlite
collations are not used, thus lowercase is applied to all non
case-sensitive columns. However, lowercasing the database requires
temporary disabling foreign key constraints, which is not possible
on SQLite and requires we specify the constraint names.

This migration specific to sqlite and postgresql drops every
constraint, whether it is named or not, and recreates all of them
with known names so we can later disable them.
7 years ago
kaiyou e022513a94 Fix support for postgres and mysql 7 years ago
kaiyou a881a1a839 Revert "Make current migrations work with postgresql"
This reverts commit 9b9f3731f6.
7 years ago
kaiyou 76925e82f3 Revert "Implement CIText as NOCASE alternative in postgresql"
This reverts commit 0f3c1b9d15.
7 years ago
kaiyou f52ae5535c Revert "Created function for returning email type"
This reverts commit 436055f02c.
7 years ago
kaiyou f6520eace6 Merge branch 'feat-psql-support' of https://github.com/usrpro/Mailu into usrpro-feat-psql-support 7 years ago
hoellen 8fe9e695f3 prefer non-wildcard aliases over wildcard aliases 7 years ago
Tim Möhlmann c7dcfee882
Merge pull request #713 from pgeorgi/extend-nginx
nginx: Allow extending config with overrides
7 years ago
hoellen 79768c09f6 fix alias matching behaviour 7 years ago
Tim Möhlmann 6ca8ed437d
Merge pull request #732 from Nebukadneza/add_front_certificate_reload
Add certificate watcher for external certs to reload nginx
7 years ago
Dario Ernst 1aa97c9914 Add certificate watcher for external certs to reload nginx
In case of TLS_FLAVOR=[mail,cert], the user supplies their own certificates.
However, since nginx is not aware of changes to these files, it cannot
reload itself e.g. when the certs get renewed.

To solve this, let’s add a small daemon in the place of
`letsencrypt.py`, which uses a flexible file-watching framework and
reloads nginx in the case the certificates change ….
7 years ago
Tim Möhlmann c00910ca4b
Merge remote-tracking branch 'upstream/master' into extend-nginx 7 years ago
Tim Möhlmann 97d338e68a
Rectify 'endif' placement 7 years ago
Tim Möhlmann 425cdd5e77
Fix syntax errors 7 years ago
Tim Möhlmann 20f1faf6d0
Send 404 when nothing server at '/'
Prevents Nginx welcome screen
7 years ago
Tim Möhlmann 2de4995fec
Don't redirect when webmail is served on '/' 7 years ago
Tim Möhlmann f0906073e3
Merge remote-tracking branch 'upstream/master' into feat-subnet2 7 years ago
mergify[bot] a634c7b72d
Merge pull request #725 from usrpro/fix-outlook2019-smtp
Add login method to smtp_auth under ssl
7 years ago
Tim Möhlmann 8172f3eab8
Move the Mailu Docker network to a fixed subnet.
This will make network configuration and host based authentication
more robust, across different deployment platforms.
The options `RELAYNETS` and`POD_ADDRESS_RANGE` are kept for compatibility.
However, their usage have become optional.
7 years ago
kaiyou b6aaf57be1 Merge branch 'refactor-config' of github.com:kaiyou/mailu into refactor-config 7 years ago
kaiyou d0f07984b0 Merge remote-tracking branch 'upstream/master' into refactor-config 7 years ago
Tim Möhlmann 9dd447e23b
Add login method to smtp_auth under ssl
Fixes #704
7 years ago
Patrick Georgi eac4d553a9 nginx: Allow extending config with overrides
To facilitate this, the default redirect at / can be disabled, even if
the default remains at redirecting to the webmailer.

The extensions are within the host scope and are read from
$ROOT/overrides/nginx/*.conf.
7 years ago
mergify[bot] 2d4bac03ad
Merge pull request #723 from usrpro/clean-healthcheck-logs
Admin: Prevent redirects during health checking
7 years ago
mergify[bot] a382f74680
Merge pull request #705 from usrpro/fix-recaptcha
Fix recaptcha
7 years ago
mergify[bot] 37027cfce7
Merge pull request #633 from kaiyou/fix-sender-checks
Improve sender checks
7 years ago
Tim Möhlmann d18cf7cb25
Prevent redirects during health checking 7 years ago
Tim Möhlmann c9df311a0d
Set forward_destination to an empty list
The value of `None` resulted in an error, since a list was expected.
7 years ago
Tim Möhlmann eff6c34632
Catch asterisk before resolve_domain
Asterisk results in IDNA error and a 500 return code.
7 years ago
Ionut Filip 7b8835070d Added tenacity retry fir migrations connection 7 years ago
David Rothera 88c174fb7a Query alternative table for domain matches
At present postfix checks this view for matches in the domain table and is used to accept/deny messages sent into it however it never checks for matches in the alternative table.

Fixes #718
7 years ago
Ionut Filip 436055f02c Created function for returning email type 7 years ago
Tim Möhlmann 47a3fd47b5
Fix DB_FLAVOR condition testing for models.py 7 years ago
Tim Möhlmann 0f3c1b9d15
Implement CIText as NOCASE alternative in postgresql 7 years ago
Tim Möhlmann 9b9f3731f6
Make current migrations work with postgresql 7 years ago
Tim Möhlmann 8bdc0c71af
Allow for setting a different DB flavor 7 years ago
Ionut Filip fed7146873 Captcha check on signup form 7 years ago
Tim Möhlmann 4783e61693
Fix password context
Fixes the following error:
```
admin_1      | [2018-11-09 09:44:10,533] ERROR in app: Exception on /internal/auth/email [GET]
admin_1      | Traceback (most recent call last):
admin_1      |   File "/usr/lib/python3.6/site-packages/flask/app.py", line 2292, in wsgi_app
admin_1      |     response = self.full_dispatch_request()
admin_1      |   File "/usr/lib/python3.6/site-packages/flask/app.py", line 1815, in full_dispatch_request
admin_1      |     rv = self.handle_user_exception(e)
admin_1      |   File "/usr/lib/python3.6/site-packages/flask/app.py", line 1718, in handle_user_exception
admin_1      |     reraise(exc_type, exc_value, tb)
admin_1      |   File "/usr/lib/python3.6/site-packages/flask/_compat.py", line 35, in reraise
admin_1      |     raise value
admin_1      |   File "/usr/lib/python3.6/site-packages/flask/app.py", line 1813, in full_dispatch_request
admin_1      |     rv = self.dispatch_request()
admin_1      |   File "/usr/lib/python3.6/site-packages/flask/app.py", line 1799, in dispatch_request
admin_1      |     return self.view_functions[rule.endpoint](**req.view_args)
admin_1      |   File "/usr/lib/python3.6/site-packages/flask_limiter/extension.py", line 544, in __inner
admin_1      |     return obj(*a, **k)
admin_1      |   File "/app/mailu/internal/views/auth.py", line 18, in nginx_authentication
admin_1      |     headers = nginx.handle_authentication(flask.request.headers)
admin_1      |   File "/app/mailu/internal/nginx.py", line 48, in handle_authentication
admin_1      |     if user.check_password(password):
admin_1      |   File "/app/mailu/models.py", line 333, in check_password
admin_1      |     context = User.pw_context
admin_1      | AttributeError: type object 'User' has no attribute 'pw_context'
```
7 years ago
kaiyou 72e1b444ca Merge alembic migrations 7 years ago
kaiyou 5b769e23da Merge branch 'master' into refactor-config 7 years ago
kaiyou 02995f0a15 Add a mailu command line to flask 7 years ago
kaiyou f9e30bd87c Update the dockerfile and upgrade dependencies 7 years ago
kaiyou 4a7eb1eb6c Explicitely declare flask migrate 7 years ago
kaiyou 2a8808bdec Add the configuration table migration 7 years ago
kaiyou f57d4859f3 Provide an in-context wrapper for getting users 7 years ago
kaiyou f6013aa29f Fix an old migration that was reading configuration before migrating 7 years ago
kaiyou 206cce0b47 Finish the configuration bits 7 years ago
Ionut Filip 1bbf3f235d Using a new class when captcha is enabled 7 years ago
mergify[bot] 12689965bd
Merge pull request #699 from usrpro/fix-admin-bug
Fixed admin_1 errors in the logs
7 years ago
hoellen 680ad4b67a
Catching only ValueError
Co-Authored-By: ionutfilip <ionut.philip@gmail.com>
7 years ago
mergify[bot] e08f3e81d0
Merge pull request #680 from usrpro/feat-startup
Standarize images
7 years ago
Ionut Filip 6dcc33e390 Fixed admin_1 errors in the logs
Fixed errors when trying to log in with an account without domain.
This closes #585
7 years ago
Tim Möhlmann 42e2dbe35d
Standarize image by using shared / similair layers 7 years ago
Tim Möhlmann 5fa2aac569
Fix imap login when no webmail selected 7 years ago
Tim Möhlmann 903bb70c5b
Merge remote-tracking branch 'upstream/master' into standarize-images 7 years ago
Scott 56fb74c502 Fix typo (duplicate self). Fixes #683 7 years ago
Ionut Filip 8a44a44688
Merge branch 'master' into feat-startup 7 years ago
Ionut Filip 1187cac5e1 Finished up switching from .sh to .py 7 years ago
Tim Möhlmann ed81c076f2
Take out "models" path, as we are already in it 7 years ago
Tim Möhlmann aed80a74fa
Rectify decleration of domain_name 7 years ago
Tim Möhlmann 2d382f2d67
Merge branch 'master' into fix-sender-checks 7 years ago
Ionut Filip 0e5606d493 Changed start.sh to start.py 7 years ago
Ionut Filip eb7dfb5771 Cleaning up start.py 7 years ago
Thomas Sänger 603b6e7390
Merge pull request #2 from usrpro/fix-nginx-healthcheck
Fix nginx healthcheck
7 years ago
Tim Möhlmann 81b24f61e8
Merge branch 'master' into feat-healthchecks 7 years ago
Tim Möhlmann a2fea36c79
Increase HEALTHCHECK start time for services that need to wait for host resolving during startup.
In Docker Swarm mode the services listed below can get stuck in their start script, while they
are waiting for other services become available. Now, with HEALTHCHECK enabled, docker does not resolve
names of services that not pass HEALTHCHECK yet. Meaning that if one of the depenend services is not yet
available, it will create a chain of failing services.

The services below retry to resolve 100 time, with an average of 3.5 seconds. Hence, the --start-time
flag is now set at 350 seconds.
- dovecot (imap)
- postfix (smtp)
- rspamd (antispam)
7 years ago
Tim Möhlmann c3e89967fb
Fix front health checking
- Specified seperated /health path in order to allow for healthcheck even if webmail and admin are not seletectd. This also allows healthchecking fom external services like DNS load balancers;
- Make curl not to fail on TLS because localhost is not included in the certificates.
7 years ago
mergify[bot] 90b8c3cc1f
Merge pull request #665 from kaiyou/feat-reply-startdate
Implement a start date filter for autoreply, fixes #362
7 years ago
mergify[bot] bce1487338
Merge pull request #576 from hacor/master
Kubernetes fixed for production
7 years ago
kaiyou 1fcaef7c7e
Merge branch 'master' into fix-sender-checks 7 years ago
Paul Williams 78bd5aea1c enable http2, because it's that easy 7 years ago
hoellen 72d4fa2bc9
remove empty line from merge conflict 7 years ago
hoellen 857ad50509
Merge branch 'master' into feat-reply-startdate 7 years ago
mergify[bot] 4a5c0a6d21
Merge pull request #667 from kaiyou/fix-password-performance
Improve password checking performance
7 years ago
mergify[bot] 80658c30da
Merge pull request #669 from hoellen/fix-webmail-root
Fix nginx conf if webmail is on root path
7 years ago
Hans Cornelis f10416e85a Merged with new PRs 7 years ago
mergify[bot] 118ea0f3fb
Merge pull request #604 from ofthesun9/feature-swarm
Enabling swarm deployment on master branch
7 years ago
mergify[bot] 727970514d
Merge pull request #527 from ofthesun9/feat-fuzzyhashes
Trying to enable fuzzy hashes for rspamd
7 years ago
kaiyou 82069ea3f0 Clean most of the refactored code 7 years ago
kaiyou f40fcd7ac0 Use click for the manager command 7 years ago
kaiyou fc24426291 First batch of refactoring, using the app factory pattern 7 years ago
hoellen d4f32c3e7d remove rewrite if webmail is on root 7 years ago
kaiyou 01fa179767 Update the user password in database when needed 7 years ago
kaiyou 988e09e65e Add a profiler in debug mode for improving performance 7 years ago
kaiyou dba8f1810d Do not check the password another time in Dovecot 7 years ago
kaiyou d5162328ec Allow dovecot to write the source configuration directory for compiling sieve scripts 7 years ago
kaiyou ce0bf3366d Learn fuzzy hashes automatically 7 years ago
kaiyou 0a5dbf6230 Re-enable local dovecot sieve scripts 7 years ago
Hans Cornelis ef55ca525c Deleted conflicting merge files
Signed-off-by: Hans Cornelis <hacornelis@gmail.com>
7 years ago
Hans Cornelis e67a0d464b Deleted old folder 7 years ago
Hans Cornelis 3098343360 Merged conflicts 7 years ago
hacor 4ea12deae7 Added kubernetes to Mailu 7 years ago
kaiyou ed3388ed6e Merge branch 'master' into feat-reply-startdate 7 years ago
kaiyou 7c82be904f Merge branch 'master' of github.com:mailu/mailu 7 years ago
Thomas Sänger a412951a30
simpler healthcheck for postfix 7 years ago
Thomas Sänger 0bc901a722
add healthcheck for dovecot 7 years ago
Thomas Sänger 1fc40bf932
add healthcheck for postfix 7 years ago
Thomas Sänger 39272ab05c
add healthcheck for http services 7 years ago
kaiyou e784556330 Fix an edge case with old values containing None for coma separated lists 7 years ago
kaiyou f647d1a0bc Merge branch 'master' into fix-sender-checks 7 years ago
kaiyou 5ada669f43 Rebase reply startdate on master 7 years ago
mergify[bot] bee81d1a54
Merge pull request #647 from HorayNarea/bcrypt
support bcrypt and use it as default
7 years ago
mergify[bot] 9fd7851cb6
Merge pull request #648 from HorayNarea/apk-no-cache
remove apk-warning about cache
7 years ago
kaiyou 15eb2806bf Merge branch 'master' into feat-reply-startdate 7 years ago
kaiyou 5035975c41 Remove Postfix debugging 7 years ago
kaiyou c6846fd8db Merge branch 'master' into feat-reply-startdate 7 years ago
mergify[bot] a91a54b5f1
Merge pull request #651 from usrpro/fix-certbot
Front: move to Alpine:3.8 and fixing #522
7 years ago
Tim Möhlmann de43060ef8
Move to Alpine:3.8 and fixing #522 7 years ago
Thomas Sänger bdfcc5b530
pin alpine-version for 'none'-image 7 years ago
Thomas Sänger 6aafef88bd
remove apk-warning about cache 7 years ago
Thomas Sänger c8b39c5d4a
support bcrypt and use it as default 7 years ago
kaiyou 10ec2f999a Another (embarrassing) fix for a merge typo 7 years ago
kaiyou 2e1aa079c1 Fix one (hopefully) last merge typo 7 years ago
kaiyou 4b9dbf00a8 Fix yet another merge-time typo 7 years ago
kaiyou e8e133b53d Fix a merge typo in postfix build 7 years ago
kaiyou 00b5ae11db
Merge branch 'master' into feat-abstract-db 7 years ago
ofthesun9 13146be57e Merge branch 'master' into feature-swarm 7 years ago
kaiyou 508e519a34 Refactor the postfix views and implement sender checks 7 years ago
kaiyou 8b189ed145 Separate senderaccess and senderlogin maps 7 years ago
ofthesun9 74796201ec Merge branch 'master' into feature-swarm 7 years ago
kaiyou fc99eb7b34 Re-enable sender access check to prevent source spoofing 7 years ago
kaiyou f3f0b98755 Fix relay restrictions so email gets delivered correctly 7 years ago
Tim Möhlmann 0817629869
Increase attempts as it failed on fresh Swarm host 7 years ago
Tim Möhlmann 716ed16f34
Fix typo 7 years ago
Tim Möhlmann 16469d7282
Upgrade to newer pip version 7 years ago
Tim Möhlmann 1bae5968ad
Import tenacy and fix syntax errors 7 years ago
Tim Möhlmann c457ccfa60
Use tenacity for resolver retries 7 years ago
Tim Möhlmann d6c386651d
Merge branch 'master' into fix-swarm-start 7 years ago
ofthesun9 09d77bc2de Handle the case where the variable REJECT_UNLISTED_RECIPIENT is not set 7 years ago
ofthesun9 cc17962c86 fixes #583 7 years ago
kaiyou 4d70a8737e Expose the data volume for admin container 7 years ago
kaiyou 2cba045013 Explicitely declare required volumes, fixes #568 7 years ago
kaiyou fcad52b145 Implement a start date filter for autoreply, fixes #362 7 years ago
kaiyou 82bb8c2fd9 Merge remote-tracking branch 'github/master' into feat-abstract-db 7 years ago
kaiyou f5668dea51 Handle relays as virtual transports through podop 7 years ago
kaiyou 9890e1fb2a Fix the dovecot configuration path 7 years ago
kaiyou 42c6bdb4df Split the internal blueprint into multiple view files 7 years ago
kaiyou dc4b0d21ea Clean the dovecot configuration dir 7 years ago
kaiyou f9c6c98180 Remove fetchmail dependency to the databse 7 years ago
kaiyou 43b6547e1c Lower the loglevel of podop 7 years ago
kaiyou 542793260b Handle wildcard aliases using podop 7 years ago
kaiyou 0d52364eac Fix alias resolution through podop 7 years ago
kaiyou 6d088504bd Adjust podop debug level based on environment 7 years ago
kaiyou 6ba55ee377 Implement the sieve script name resolution pattern 7 years ago
kaiyou 3c725bf634 Only support generating the default sieve script 7 years ago
kaiyou ca6c0bc8fd Fix the user sieve script generation 7 years ago
kaiyou 4d25083847 Move sieve script generation to the admin container 7 years ago
kaiyou cfeaa189f9 Use proper 404 return codes for missing objects 7 years ago
kaiyou d8365bfbcf Use simpler routes for Dovecot 7 years ago
kaiyou 697caaab81 Update podop access and mail restrictions 7 years ago
kaiyou 7143fb8c47 Implement some basic views for podop 7 years ago
kaiyou 39cd0d5034 Upgrade to alpine 3.8 for smtp and imap 7 years ago
kaiyou 68aa797720 Merge branch 'master' into feat-abstract-db 7 years ago
ofthesun9 f5f09fad6e Reverting the patch for dovecot.conf, as it is not needed 7 years ago
Thomas Sänger 0b885548ab
bind to any protocol 7 years ago
kaiyou 73ca5fb3d3 Provide a more generic skeletton for postfix virtual lookups 7 years ago
ofthesun9 23e288aadc Enabling swarm deployment on master branch:
-Extends the usage of POD_ADDRESS_RANGE
-Provides documentation
7 years ago
kaiyou 5dc9ee9516
Merge pull request #510 from hoellen/spam-trash-fix
Dont flag spam as ham if moved to trash
7 years ago
kaiyou d917f60352
Merge pull request #553 from HorayNarea/compress
add optional Maildir-Compression
7 years ago
kaiyou 64269e08c0
Merge pull request #552 from HorayNarea/master
add full-text search support
7 years ago
kaiyou 313b79538e
Merge pull request #513 from mprihoda/feature/better-ratelimit-error
Return correct status codes from auth rate limiter failure.
7 years ago
Tim Möhlmann cc8e15748b Retry 10 times when resolving fails in start.py scripts 7 years ago
Thomas Sänger 0bdb2a16bc
add optional Maildir-Compression 7 years ago
Thomas Sänger fb62e6b5a2
add full-text search support 7 years ago
kaiyou f506966abc Pin Alpine 3.7 to preserve the Postfix version 7 years ago
Tim Möhlmann 9350bb9b9a Use fixed alpine:3.7 tag to prevent postix upgrade 7 years ago
Pierre Jaury 3dca1a834c Pin alpine 3.7 until we fix the certbot issue, see #522 7 years ago
Pierre Jaury 18fe8cd9f2 Pin alpine:3.7 for Dovecot since extdata was removed from repos, fixes #528 7 years ago
Pierre Jaury 5ad02ae2e5 Use a more uniform 'Save' for most form submits, fixes #523 7 years ago
Pierre Jaury c04e58498d Remove unused postfix sqlite files 7 years ago
Pierre Jaury bb73933e1e Switch postfix to Podop 7 years ago
Pierre Jaury 82e738cc53 Remove the old code of postproxy 7 years ago
Pierre Jaury b5d6b93869 Switch to using Podop in Dovecot 7 years ago
Pierre Jaury 809fe78f82 Add dovecot views to the internal API 7 years ago
Pierre Jaury 28001213d4 Remove the redis-based quota code 7 years ago
Pierre Jaury 76617a3c97 Store the quota status in database 7 years ago
Pierre Jaury 2b2ab864d1 Add support for querying the table in Dovecot proxy 7 years ago
Pierre Jaury 70175f8c28 Add postproxy support for Dovecot dict protocol 7 years ago
Pierre Jaury 262e82a367 Add a postfix socketmap to http proxy 7 years ago
Michal Prihoda f5e7751835 Return correct status codes from auth rate limiter failure. 7 years ago
hoellen ca26264d01 Dont flag spam as ham if moved to trash (fix #474) 7 years ago
kaiyou 75a1bf967c
Merge pull request #502 from hoellen/webmail-messagesize
Use message_size_limit variable from env for webmail client_max_body_size
7 years ago
hoellen c51e1b9eef webmail client_max_body_size with message_size_limit and 8M tolerance 7 years ago
kaiyou 74b72375cb
Merge pull request #493 from MFAshby/user_validation
Made User and UserSignup validation consistent for the local part of
7 years ago
kaiyou 53bf6085dc
Merge pull request #501 from hoellen/webmail-root
Add posibilty to run webmail on root '/'
7 years ago
hoellen 9091e54fda Hide administration header in sidebar for normal users. 7 years ago
hoellen 81a6a7cbf6 Use message_size variable from env for webmail 7 years ago
hoellen a1fb8442e3 Add posibilty to run webmail on root '/' 7 years ago
mfashby 0284b6a8e9 Made User and UserSignup validation consistent for the local part of the email address 7 years ago
Pierre Jaury 14687d09ba Fix announcements for idna domains 8 years ago
Pierre Jaury e543477c2e Revert "Only enable milter for incoming emails"
This reverts commit cfd233039e.
8 years ago
Pierre Jaury cfd233039e Only enable milter for incoming emails 8 years ago
Pierre Jaury 6828231c28 Fix the path of the nginx pid in startup scripts, fixes #483 8 years ago
Pierre Jaury 1b0b3a2b1e Only check login mismatch for authenticated users, fixes #309 8 years ago
Pierre Jaury 1371ba5f5e Add the keep field to fetch forms, fixes #479 8 years ago
Pierre Jaury ea658a174d Fix a typo in the base html template 8 years ago
Pierre Jaury b6c76a5e39 Do not remove openssl when purging build deps, fixes #481 8 years ago
kaiyou a47ba3474c
Merge pull request #448 from romracer/pod-address
Use POD_ADDRESS_RANGE for Dovecot if it exists
8 years ago
kaiyou 3beceb90ec
Merge pull request #429 from mildred/parametrize-hosts
Add various environment variables to allow running outside of docker-compose
8 years ago
kaiyou a9e41960a1
Merge pull request #468 from dtwardow/flex_tls_filenames
TLS using configurable filenames
8 years ago
kaiyou 91e51a24c8
Merge pull request #465 from sanduhrs/feature/463
Remove services status page
8 years ago
Thomas Sänger 7d661ab80d
don't require BootstrapCDN for FontAwesome (GDPR-compliance) 8 years ago
Mildred Ki'Lya 6bb4c6e2f0 Parametrize front address from dovecot 8 years ago
Mildred Ki'Lya ae8c9f5a6b Add various environment variables to allow running outside of docker-compose 8 years ago
Dennis Twardowsky 50f9f379e9 Flexible filenames for TLS via envvars (flavours 'cert' and 'mail' only) 8 years ago
Stefan Auditor 6177571e4d Remove services status localization 8 years ago
Stefan Auditor b541d4c257 Remove services status sidebar link 8 years ago
Stefan Auditor e89b32a3f4 Remove services route 8 years ago
Stefan Auditor ec8e82aaca Remove services status template 8 years ago
kaiyou f55e5e26cd Update messages.po (POEditor.com) 8 years ago
kaiyou 2b96abbef4 Update messages.po (POEditor.com) 8 years ago
kaiyou af38d5ab0c Update messages.po (POEditor.com) 8 years ago
kaiyou fc89b30e8a Update messages.po (POEditor.com) 8 years ago
kaiyou 791fab688a Update messages.po (POEditor.com) 8 years ago
kaiyou c9b0832899 Update messages.po (POEditor.com) 8 years ago
kaiyou fa1b0ac32c Update messages.po (POEditor.com) 8 years ago
kaiyou 75f0791965 Update messages.po (POEditor.com) 8 years ago
kaiyou c91c5c7493 Update messages.po (POEditor.com) 8 years ago
kaiyou 299a654e97 Update messages.po (POEditor.com) 8 years ago
kaiyou 494e52d8f0 Update messages.po (POEditor.com) 8 years ago
kaiyou 3b7014d563 Add dummy spanish and russion languages 8 years ago
kaiyou be0a0b4ac8 Update translation strings 8 years ago
kaiyou 8bad30cd59 Move the domain MX status to the detail page 8 years ago
kaiyou 7f0447514c Finish storing the user quota to redis 8 years ago
kaiyou 80893be68b Add a missing import to dnspython 8 years ago
kaiyou 091369915b Display the user quota in the admin interface 8 years ago
kaiyou e13593f29a Switch to database 2 for rate limiting 8 years ago
kaiyou d1dbba2d3a Add expose instructions in Dockerfiles, fixes #392 8 years ago
kaiyou 62d1a0c104 Add a status field to the domain list 8 years ago
kaiyou bb0d7bf6dc Enforce the nocase collation on the email table 8 years ago
kaiyou 186c30d2ac Have the admin listen on ipv6 8 years ago
kaiyou 35276c3101
Merge pull request #458 from Farthen/master
Dovecot: Add SQL iterate_query to config file.
8 years ago
kaiyou dfaedb76f1
Merge pull request #447 from sanduhrs/feature/446
Add a sqlalchemy custom type for unicode to idna conversion of domain names
8 years ago
farthen f75280e4a3 Dovecot: Add SQL iterate_query to config file.
This allows to use doveadm -A to execute maintenance tasks for all users on the server
8 years ago
kaiyou 9968d708f1 Update the prod requirements 8 years ago
kaiyou 381e76511d Add self-service domain registration 8 years ago
Stefan Auditor c688970b32 Respect user enabled flag in admin authentication 8 years ago
Stefan Auditor d3064579f4 Respect user enabled flag in basic authentication 8 years ago
Stefan Auditor 92f4858323 Respect user.enabled status in internal authentication 8 years ago
Stefan Auditor d2c6cecca6 Remove is_enabled method and use the enabled attribute instead 8 years ago
Stefan Auditor 5bfdd75738 Respect user enabled flag on user.login 8 years ago
Stefan Auditor 78f4fa7db9 Add field to ui for user enabled flag 8 years ago
Stefan Auditor 20d6fbae48 Add enabled flag to user model 8 years ago
Scott 2c2a1ed042 Remove stale link to old auto-forward settings. Fixes #450
Also update a reference to 'smtp' to use HOST_AUTHSMTP
8 years ago
kaiyou a51416a4af
Merge pull request #452 from sanduhrs/feature/449
Add enabled flag to user model
8 years ago
Stefan Auditor e843f7ef1f Respect user enabled flag in admin authentication 8 years ago
Stefan Auditor c8540ddba7 Respect user enabled flag in basic authentication 8 years ago
Stefan Auditor 6fc22e5432 Respect user.enabled status in internal authentication 8 years ago
Stefan Auditor 733b89bff5 Remove is_enabled method and use the enabled attribute instead 8 years ago
Stefan Auditor 3b66fcada7 Respect user enabled flag on user.login 8 years ago
Stefan Auditor 7139a27bf1 Add field to ui for user enabled flag 8 years ago
Stefan Auditor f585197e52 Add enabled flag to user model 8 years ago
Scott e5c25c395f Remove stale link to old auto-forward settings. Fixes #450
Also update a reference to 'smtp' to use HOST_AUTHSMTP
8 years ago
Stefan Auditor 7f5bd98a2e Add parameters to database field 8 years ago
Stefan Auditor 93d5254b3f Add another type decorator for idna email support 8 years ago
Scott 6018995534 Use POD_ADDRESS_RANGE for Dovecot if it exists
This is required to override allow_nets in a Kubernetes environment where pods are not recreated with the same IP address.
8 years ago
Stefan Auditor 792c720c13 Save user email domain_name as idna representation 8 years ago
Stefan Auditor c40e255f3b Reset relay columns to string 8 years ago
Stefan Auditor d9ea64fac7 Import idna library and move code a bit upwards 8 years ago
Stefan Auditor 5a7272ff12 Replace other occurences of domain names with idna 8 years ago
Stefan Auditor 1b666cd25b Add a sqlalchemy custom type for unicode to idna conersion of domain names 8 years ago
kaiyou db0cd8efb4 Fix the client setup page when not logged in 8 years ago
kaiyou e92113bd57
Merge pull request #433 from mildred/delivered-to-hdr
Add original Delivered-To header to received messages
8 years ago
kaiyou b4134b7774 Add a client setup page, fixes #342 8 years ago
kaiyou fa0bda7b69 Merge the auto-forward and antispam settings 8 years ago
kaiyou 3ef4e1f6b7 Add support for recaptcha upon signup 8 years ago
kaiyou e02e47c48e
Merge pull request #416 from calebj/patch-1
Add support for sending from alternative domains
8 years ago
Scott b9e67635f4 Use HOST_ADMIN in "Forwarding authentication server". Fixes #436. 8 years ago
Mildred Ki'Lya 649a4fc9cf Add Delivered-To header to received messages
Postfix, after expanding the alias, is not transmitting the original
envelope recipient email address to dovecot and cannot record it in a
Received: header.

The LMTP DSN extension allows postfix to specify an ORCPT= parameter to
the "RCPT TO:" line (in postfix src/smtp/smtp_proto.c). However, dovecot
does not support the DNS extension on the LMTP endpoint. It has
preliminary support of the ORCPT parameter in latest versions but is is
disabled and not working.

The solution taken was to add a sieve script to parse the Received:
header written by postfix and parse the original RCPT TO address from
it. Then add the header through the "editheader" sieve extension. Later
sieve scripts can take this header to perform further filtering.
8 years ago
Caleb Johnson b58dcfb511
Add support for sending from alternative domains
See Mailu/Mailu#415
8 years ago
AdrienM 29a1548532 Add explicit ssl_protocols in conf 8 years ago
kaiyou dfb5463c94 Relax the frame filtering to allow roundcube to display previews 8 years ago
kaiyou 04278b6cbf Pass the full host to the backend, fixes #372 8 years ago
kaiyou 6c56c8e298 Specify the client max body size in the front, related to #371 8 years ago
Mildred Ki'Lya f538e33dcf Parametrize hosts
Allows to use mailu without docker-compose when hostnames are not set up
by docker itself but provided via a separate resolver.

Use case: use mailu using nomad scheduler and consul resolver instead of
docker-compose. Other servers are provided by the DNS resolver that
resolves names like admin.service.consul or webmail.service.consul.
These names needs to be configurable.
8 years ago
kaiyou d8ebfbe020 Display infinite user quotas correctly, fixes #368 8 years ago
SunMar 6ec0fe7036 Adding options for mail-letsencrypt 8 years ago
kaiyou d98f16333a Display an infinite quota when necessary for users, fixes #345 8 years ago
kaiyou 8d224824ea Display a conditional button for generation dkim keys, fixes #346 8 years ago
kaiyou d0b8de72e4 Do not deny HTTP access upon TLS error when the flavor is mail 8 years ago
kaiyou bfc898c2d8 Move dhparam to /conf 8 years ago
Greg Fitzgerald f1ad2cf4d0 Use a predefined dhparam.pem, This fixes issue #322 8 years ago
kaiyou 7a9d2c9725
Merge pull request #353 from ripkens/patch-1
Added adress verification before accepting mails for delivery
8 years ago
kaiyou acb5d7da38 Use relative redirect for / to the webmail 8 years ago
kaiyou 2dfc91ac4d Use a map for passing x-forwarded-proto along 8 years ago
Marcus Ripkens 7375134474
Update main.cf 8 years ago
Marcus Ripkens 175349a224
Added adress verification before accepting mails for delivery
See https://www.endpoint.com/blog/2015/05/28/postfix-address-verification

Block client until address verifiction is completed and mail will not be rejected by relaying MTA or smarthost.
If verification fails, mail is rejected.
If verification takes too long, mail is temporaryly rejected and sending client will retry later.
8 years ago
kaiyou 42314d3d75 Remove a remaining rebug print() statement 8 years ago
kaiyou a4f46ced49 Properly use x-forwarded-proto with redirects in the webui, related to #347 8 years ago
kaiyou 48d736feef Configure a resolver for the mail server to populate xclient hostnames 8 years ago
rageOS 59766d289e
Fix for relayed Domains 8 years ago
kaiyou 319965a4af Add a format check for the email localpart when signing up 8 years ago
kaiyou 18ae6a4a0f Fix the signup quota 8 years ago
kaiyou e85eada522 Fix the login view when no next page is provided 8 years ago
kaiyou def0a8b89d Fix the signup domain list with non infinite mailbox max count 8 years ago
kaiyou 2662abedef Enable self-service account signup 8 years ago
kaiyou 3b79e5196a Add a default quota setting for new accounts 8 years ago
kaiyou 6d71fa96ad Add a signup field to domains 8 years ago
kaiyou 4761646616 Make sure stale pid files are dealt with, fix #341 8 years ago
kaiyou 743eb81908 Fix the Webdav behavior with Radicale, related to #334 8 years ago
kaiyou 328001a417
Merge pull request #329 from HorayNarea/patch-1
Disable ssl_session_tickets, see https://wiki.mozilla.org/Security/Server_Side_TLS#TLS_tickets_.28RFC_5077.29
8 years ago
kaiyou c545b8d110 Honor feature limitations for imap and pop3 8 years ago
kaiyou 3e464b0b70 Update messages.po (POEditor.com) 8 years ago
kaiyou 952a50665b Update messages.po (POEditor.com) 8 years ago
kaiyou d4441b6815 Move nl and sv loca to LC_MESSAGES 8 years ago
kaiyou ab34ce4e8e Add dummy files for pl and it loca 8 years ago
kaiyou 2f4758a445 Update messages.po (POEditor.com) 8 years ago
kaiyou e368c200b1 Update messages.po (POEditor.com) 8 years ago
kaiyou f3ae318132 Perform webdav authentication in nginx, fixes #330 8 years ago
kaiyou 17b184e5c8 Implement a basic authentication API 8 years ago
kaiyou 8920982213 Properly pass the request uri to the authentication backend 8 years ago
kaiyou 97dd9ed77c Fix a missing variable in the nginx config 8 years ago
Thomas Sänger d61ba8e651
disable ssl_session_tickets 8 years ago
kaiyou eb32871904 Force nginx to run dns queries at runtime 8 years ago
Thomas Sänger ad7c5e48c5
automatically set nginx-worker based on CPU-count 8 years ago
kaiyou 059cbb37a4 Update messages.po (POEditor.com) 8 years ago
kaiyou e9f4719a40 Update messages.po (POEditor.com) 8 years ago
kaiyou 112cff3621 Update messages.po (POEditor.com) 8 years ago
kaiyou f30a09f182 Update messages.po (POEditor.com) 8 years ago
kaiyou 826d212a75 Update messages.po (POEditor.com) 8 years ago
kaiyou 72029ca220 Update messages.po (POEditor.com) 8 years ago
kaiyou aa9a065d5b Update messages.po (POEditor.com) 8 years ago
kaiyou 2e370e3731 Update messages.po (POEditor.com) 8 years ago
kaiyou ebddc7bec2 Add dummy translations for swedish and dutch 8 years ago
kaiyou f362ecdb19 Fix the missing trailing space on /webmail, fixes #304 8 years ago
kaiyou 652ca769dc Allow authentication from webmail directly, fixes #308 8 years ago
kaiyou 28eff398d1 Send a vacation response only until the end date, fixes #218 8 years ago
kaiyou 011e1fa52d Add an end of vacation field, related to #218 8 years ago
kaiyou fb42797ab7 Use SITENAME and WEBSITE properly in the admin ui 8 years ago
kaiyou 872271cb47 Clean the configuration variable list 8 years ago
kaiyou 1a3f85fbc2 Make the rspamd webui available, fixes #157 8 years ago
kaiyou ac0c339aa8 Implement welcome emails, fixes #107 8 years ago
kaiyou 570e90acbc Move email send features to the User model 8 years ago
kaiyou 92f2025d7c Enable pop3 on the frontend, fix #313 8 years ago
kaiyou 6e61500eb1 Fix the authentication behavior with non-existing users 8 years ago
HouMingtao [侯明涛] b0f8d7ab78 move to new translation folder
Change-Id: If4b4a25b305aab3d96155283881573a125272f81
8 years ago
kaiyou 2427544972 Move statistics to the start.sh script for clarity 8 years ago
kaiyou e9813f99bf Fix the annonucement feature by sending mail to the proper smtp server, fixes #309 8 years ago
kaiyou bfa50c5aa7 Add a new TLS flavor named 'mail' 8 years ago
kaiyou 6eaffd514d Make it possible to opt out of statistics 8 years ago
kaiyou 45902ae012 Fix a bug when trying to authenticate with a non existing user 8 years ago
kaiyou baff8dd043 Avoid blacklisting the webmail 8 years ago
kaiyou e625bc9adb Update the milter port on Postfix 8 years ago
kaiyou f5ee77519e Rename spam threshold to spam tolerance 8 years ago
kaiyou 1d9b3b00a7 Use rspamd as a milter service instead of deprecated rmilter 8 years ago
kaiyou edbea372e9 Merge branch 'master' into refactor-repo 8 years ago
kaiyou ac53b3ed97 Merge branch 'master' into refactor-repo 8 years ago
kaiyou 689be5f2d9 Move all directories per theme 8 years ago